wangEditor was discovered to contain a cross-site scripting (XSS) vulnerability via the image upload function
- Severity:
- Medium
Description
There is a cross-site scripting (XSS) issue in wangEditor via the image upload function in version 4.7.11. This issue has been fixed in version 4.7.12.
Recommendation
Update the @wangeditor/editor package to the latest compatible version. Followings are version details:
- Affected version(s): <= 4.7.11
- Patched version(s): 4.7.12
References
Related Issues
- @dependencytrack/frontend vulnerable to Persistent Cross-Site-Scripting via Vulnerability Details - CVE-2022-39350
- Reflected cross-site scripting (XSS) vulnerability - CVE-2022-0087
- Jodit has cross-site scripting (XSS) via <script> nested in SVG that bypasses clean-html sanitization - CVE-2026-65841
- Decap CMS Cross Site Scripting (XSS) vulnerability - CVE-2025-57520
You might also like:
- Tags:
- npm
- @wangeditor/editor
Anything's wrong? Let us know Last updated on June 11, 2026


